<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Digital Offensive &#187; Security Advisories</title>
	<atom:link href="http://www.digitaloffensive.com/category/advisories/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.digitaloffensive.com</link>
	<description>Take an offensive approach to Security know what your foes know!</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:06:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.5.3" -->
	<copyright>Copyright &#xA9; 2010 Digital Offensive </copyright>
	<managingEditor>genxweb@gmail.com</managingEditor>
	<webMaster>genxweb@gmail.com</webMaster>
	<category>posts</category>
	<ttl>1440</ttl>
	<image>
		<url>http://digitaloffensive.com/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Digital Offensive &#187; Security Advisories</title>
		<link>http://www.digitaloffensive.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Take an offensive approach to Security know what your foes know!</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Society &amp; Culture" />
	<itunes:author></itunes:author>
	<itunes:owner>
		<itunes:name></itunes:name>
		<itunes:email>genxweb@gmail.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://digitaloffensive.com/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Blue Coat URL Redirection Vulnerability</title>
		<link>http://www.digitaloffensive.com/2010/04/blue-coat-url-redirection-vulnerability/</link>
		<comments>http://www.digitaloffensive.com/2010/04/blue-coat-url-redirection-vulnerability/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 18:09:34 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security Advisories]]></category>

		<guid isPermaLink="false">http://www.digitaloffensive.com/?p=193</guid>
		<description><![CDATA[Blue Coat URL Redirection Vulnerability The Blue Coat web filter is one of the industry’s leading web filtering solutions. It provides the organization the ability to filter where their employee’s, vendors, customers or guests can go online. The Blue Coat Web filter has an issue where it will display a base64 encoded URL in the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>Blue Coat URL Redirection Vulnerability</strong></p>
<p style="text-align: left;">The Blue Coat web filter is one of the industry’s leading web filtering solutions. It provides the organization the ability to filter where their employee’s, vendors, customers or guests can go online.</p>
<p style="text-align: left;">The Blue Coat Web filter has an issue where it will display a base64 encoded URL in the following format http://blue_coat_name/?cfru=aHR0cDovL3d3dy5nb29nbGUuY29tLw== when it has an error.</p>
<p style="text-align: left;"><a href="http://www.digitaloffensive.com/wp-content/uploads/2010/04/bluecoat.jpg" target="_blank"><img class="aligncenter size-medium wp-image-194" title="bluecoat" src="http://www.digitaloffensive.com/wp-content/uploads/2010/04/bluecoat-300x121.jpg" alt="" width="300" height="121" /></a></p>
<p style="text-align: left;">
<p style="text-align: left;"><a href="http://www.digitaloffensive.com/wp-content/uploads/2010/04/bluecoat.jpg" target="_blank"><span id="more-193"></span></a></p>
<p style="text-align: left;">This URL is displayed in the end users browser usually with a message relating to the issue. The encoded URL is the URL that the end user was trying to get to before the error occurred. In the URL above I was trying to access www.google.com.  To verify that we can use any base64 decoder, for this example I used an online version found at <a href="http://base64-encoder-online.waraxe.us/" target="_blank">http://base64-encoder-online.waraxe.us/</a> .</p>
<p style="text-align: left;"><a href="http://www.digitaloffensive.com/wp-content/uploads/2010/04/encoded.jpg"><img class="aligncenter size-medium wp-image-195" title="encoded" src="http://www.digitaloffensive.com/wp-content/uploads/2010/04/encoded-300x224.jpg" alt="" width="300" height="224" /></a><a href="http://www.digitaloffensive.com/wp-content/uploads/2010/04/decoded.jpg"><img class="aligncenter size-medium wp-image-196" title="decoded" src="http://www.digitaloffensive.com/wp-content/uploads/2010/04/decoded-300x224.jpg" alt="" width="300" height="224" /></a></p>
<p style="text-align: left;">All a malicious user would need to carry out an attack would be remote site that is hosting a malicious payload or an attack platform like Metasploit or Core Impact to host the malicious file. The attacker would than use a base64 encoder to encrypt the malicious URL and send the problematic link to the system administrator or any other end user. This attack could lead to a full system compromise depending on the payload and the rights of the user clicking the URL.</p>
<p>The limitation to this vulnerability is that DNS name and or IP of the Blue Coat web appliance will differ for the majority of companies. Though I bet there are at least a few companies out there that have named their Blue Coat web filter “proxy” or “webproxy”. By posting several of these generic names on the internet it may also be able to compromise other remote machines as well.</p>
<p>The question that I have to Blue Coat is why you would provide such functionality. Why don’t  just display the URL in clear text.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.digitaloffensive.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.digitaloffensive.com/2010/04/blue-coat-url-redirection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHPizabi: Possible vulnerability in information disclosure and database integrity</title>
		<link>http://www.digitaloffensive.com/2009/09/phpizabi-possible-vulnerability-in-information-disclosure-and-database-integrity/</link>
		<comments>http://www.digitaloffensive.com/2009/09/phpizabi-possible-vulnerability-in-information-disclosure-and-database-integrity/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 13:39:56 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[Security Advisories]]></category>

		<guid isPermaLink="false">http://digitaloffensive.com/?p=7</guid>
		<description><![CDATA[PHPizabi: Possible vulnerability in information disclosure and database integrity Vendor: Notified. I notified the vendor of this issue over three months ago and have not heard back from them regarding this threat. According to their website there has been no patches or core releases released since the ones I have listed below. Version: PHPizabi 0.848b [...]]]></description>
			<content:encoded><![CDATA[<p><strong>PHPizabi: Possible vulnerability in information disclosure and database integrity</strong></p>
<p><strong>Vendor:</strong> Notified. I notified the vendor of this issue over three months ago and have not heard back from them regarding this threat. According to their website there has been no patches or core releases released since the ones I have listed below.</p>
<p><strong>Version:</strong> PHPizabi 0.848b C1 HFP1 (Alicia)</p>
<p><strong>Hot fixes: </strong> 848 Core HotFix Pack 3 0848bC1_HFP3.zip and below</p>
<p><strong>Product Info:</strong></p>
<p>“More than a simple script, dating script, or even just a matchmaker; PHPizabi is a feature rich social networking platform that integrates everything you need to jumpstart your community, dating site, or social networking portal right out of the box. PHPizabi is one of the most reliable, safe, and solid platforms on the market, offering your users features they could only dream of.”</p>
<p><strong>Vulnerability:</strong></p>
<p>In the default configuration and installation of this script the “system” dir is left open allowing indexing. When I discovered that the system dir was open I was able to download the configuration file that contained sensitive information about the site such as the database connection information including username and password.</p>
<p><strong>To exploit</strong></p>
<p>1)      Google: “Powered by PHPizabi”</p>
<p>2)      http://sitename.com/system/</p>
<p>3)      Download file open in editor.</p>
<p>Temp solutions:</p>
<p>1)      Add a .htacess to the system dir that says</p>
<p>a.       Options –Indexes</p>
<p>b.      Note this will not stop the attacker from using wget and http://sitename.com/system/config.inc.php from retrieving the file.</p>
<p>2)      Make sure that the database can only be accessed local.</p>
<p>a.       The host I had permission to test this on had the database open to remote connections.</p>
<p>Vendor should have the file die if trying to access it directly like they do if you try to access a file in the admin directory directly.</p>
<p>Tested on: This has been tested against my site www.xxxxxxxx.com I have done some edits to the code to protect my site and contacted the host about the database settings. Site address has been “X” out to protect it from people trying the attack against it.</p>
<p>Vulnerability Classification: Possible vulnerability in information disclosure and database integrity.</p>
<p>Thanks</p>
<p>Michael LaSalvia</p>
<p>www.digitaloffensive.com</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.digitaloffensive.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.digitaloffensive.com/2009/09/phpizabi-possible-vulnerability-in-information-disclosure-and-database-integrity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
